# OpenCTI AI agent for Slack & Microsoft Teams

Viktor is an AI employee that connects to OpenCTI with a scoped API key and helps you screen for fraud, malware, and security threats the way a teammate would. Ask in plain English in Slack or Microsoft Teams; Viktor does the work in OpenCTI and reports back. Setup takes about two minutes.

- Tool: OpenCTI
- Category: Productivity
- Connection: API key
- Works from: Slack and Microsoft Teams
- Page: https://viktor.com/integrations/opencti

## What can you ask Viktor to do in OpenCTI?

- "Check this IP address against OpenCTI and tell me if it's flagged."
- "Watch OpenCTI for a new threat matching our domain and alert me right away."
- "Run this file through OpenCTI and summarize the scan results."
- "Pull this week's flagged signups from OpenCTI and post a summary every Monday."

## What can Viktor do in OpenCTI?

Viktor works with OpenCTI through a managed connector to help you screen for fraud, malware, and security threats: describe the task in plain English and Viktor figures out the right OpenCTI calls, runs the work, and reports back.

## How does Viktor work with OpenCTI?

1. Add Viktor to Slack or Microsoft Teams.
2. Connect OpenCTI with an API key - Viktor handles authentication.
3. Ask in plain English. Viktor runs the OpenCTI actions, chains them with your other tools when needed, and reports back. Sensitive actions wait for your approval.

## What is a OpenCTI AI agent?

A OpenCTI AI agent is an AI that connects to your OpenCTI account and completes work in it - it doesn't just answer questions about OpenCTI, it takes the actions. Viktor is that agent: an AI employee that works in OpenCTI on your behalf and delivers the finished result in Slack or Microsoft Teams.

Unlike workflow builders such as Zapier or Make, there is nothing to configure - no triggers to map, no workflows to maintain. You describe the outcome in plain English, and Viktor picks the right OpenCTI actions, chains them with the other 3,200+ tools it connects to, and asks for approval before anything sensitive runs.

### About OpenCTI

Organize your cyber threat intelligence to enhance and disseminate actionable insights with our open-source threat intelligence platform.

## Security and permissions

- Scoped API keys - Viktor stores your key securely, uses only the scopes you grant, and you can revoke it at any time.
- Review-first approvals: sensitive OpenCTI actions wait for your sign-off before they run.
- Isolated compute per team, encrypted in transit and at rest - and your data is never used to train models.
- SOC 2 Type 1 compliant, with Type 2 and ISO 27001 in progress.

## FAQ

### Does Viktor integrate with OpenCTI?

Yes. OpenCTI is one of the 3,200+ tools Viktor connects to, via a managed connector. Once connected, anyone on your team can put Viktor to work in OpenCTI from Slack or Microsoft Teams - no workflow builder, no code.

### How do I connect OpenCTI to Viktor?

Ask Viktor in Slack or Microsoft Teams to connect OpenCTI, then paste an API key from your OpenCTI account when prompted. Viktor stores the key securely, uses only the scopes you grant, and you can revoke it at any time. Setup takes about two minutes.

### What can Viktor do in OpenCTI?

Viktor works with OpenCTI through a managed connector to help you screen for fraud, malware, and security threats: describe the task in plain English and Viktor figures out the right OpenCTI calls, runs the work, and reports back with the result in Slack or Microsoft Teams.

### Do I need to build workflows to automate OpenCTI?

No. Viktor isn't a workflow builder - there are no triggers to map and no workflows to maintain. You ask for the outcome in plain English in Slack or Microsoft Teams, and Viktor decides which OpenCTI actions to take, runs them, and reports back.

### Is my OpenCTI data secure with Viktor?

Yes. Viktor connects to OpenCTI with a scoped API key, runs in an isolated environment per team, and never trains models on your data. Sensitive actions wait for your approval, and you can revoke access at any time. Viktor is SOC 2 Type 1 compliant, with Type 2 and ISO 27001 in progress.

### How much does the OpenCTI integration cost?

Nothing extra - every integration, including OpenCTI, is available on every plan. You can start free with up to $100 in credits, no credit card required; paid plans start at $50/month.

### Can Viktor use OpenCTI together with my other tools?

Yes - that's the point. Viktor connects to 3,200+ tools and works across them in a single run: it can pull data from OpenCTI, cross-reference it with another tool - for example Slack or Gmail, and deliver the finished result in Slack or Microsoft Teams.

## Viktor uses OpenCTI together with

- [Slack](https://viktor.com/integrations/slack)
- [Gmail](https://viktor.com/integrations/gmail)
- [Google Sheets](https://viktor.com/integrations/google-sheets)
- [HubSpot](https://viktor.com/integrations/hubspot)
- [Notion](https://viktor.com/integrations/notion)
- [Salesforce](https://viktor.com/integrations/salesforce)

## More Productivity integrations

- [GitHub](https://viktor.com/integrations/github)
- [Asana](https://viktor.com/integrations/asana)
- [Basecamp](https://viktor.com/integrations/basecamp)
- [Monday.com](https://viktor.com/integrations/monday-com)
- [Jira](https://viktor.com/integrations/jira)
- [Linear](https://viktor.com/integrations/linear)
- [Miro](https://viktor.com/integrations/miro)
- [ServiceM8](https://viktor.com/integrations/servicem8)

## Get started

Viktor is free to start - up to $100 in credits, no credit card required. All 3,200+ integrations are included on every plan. Sign up at https://viktor.com or browse all integrations at https://viktor.com/integrations.
